Log In

Beware: a new wave of Cryptolocker attacks is targeting Australians

Cryptolocker is a nasty form of malware that encrypts files on the victim's computer and holds them to ransom. Pay up, and your files are decrypted - at least in theory, though there have been reports of cases where victims have paid the ransom but their files remained unusable.

A good backup regime can help protect against this type of malware - you don't need to decrypt a file if you have a copy of it - but there's always the possibility that a new and hard to recreate file may be encrypted before it is backed up.

A new wave of Cryptolocker attacks is targeting Australians and demands a ransom of $450 if paid promptly, rising to $1000 if victims delay payment.

According to Symantec, the malware arrives in the form of a zip archive that "uses the name of a major courier firm in its file name."

A lot of businesses use couriers, so this is a fairly good way of tricking people into running malware. It's a similar strategy to the fake ATO http://www.bit.com.au/News/350337,this-is-what-the-scam-australian-taxation-office-email-looks-like.aspx and Westpac http://www.bit.com.au/News/336536,warning-westpac-scam-alert.aspx malware campaigns we reported two years ago.

Unfortunately, Symantec's warning about the latest Cryptolocker campaign paid more attention to the appearance of the malware once it executes (it uses the 'Los Pollos Hermanos' branding from the TV show Breaking Bad) rather than giving clues about how we can recognise the emails that are used to deliver it.

Symantec's - and presumably other vendors' - security software can detect this Cryptolocker variant, but always think twice before opening attachments. For example, is the purported sender actually one of your customers or suppliers, and are there any indications that the email might not really be from that organisation?

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.Your use of this website
constitutes acceptance of nextmedia's Privacy Policy and
Terms & Conditions.